Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-24696
MEDIUM 6.8 Réseau 1 apps

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to …

CVE-2024-24695
MEDIUM 6.8 Réseau 1 apps

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to …

CVE-2024-24690
MEDIUM 5.4 Réseau 4 apps

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-21377
MEDIUM 5.5 Local

Windows DNS Information Disclosure Vulnerability

CVE-2024-21362
MEDIUM 5.5 Local

Windows Kernel Security Feature Bypass Vulnerability

CVE-2024-21356
MEDIUM 6.5 Réseau

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-21344
MEDIUM 5.9 Réseau

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-21343
MEDIUM 5.9 Réseau

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-21341
MEDIUM 6.8 Physique

Windows Kernel Remote Code Execution Vulnerability

CVE-2024-21340
MEDIUM 4.6 Physique

Windows Kernel Information Disclosure Vulnerability

CVE-2024-21339
MEDIUM 6.4 Physique

Windows USB Generic Parent Driver Remote Code Execution Vulnerability

CVE-2024-21304
MEDIUM 4.1 Local

Trusted Compute Base Elevation of Privilege Vulnerability

CVE-2024-20684
MEDIUM 6.5 Local

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-0753
MEDIUM 6.5 Réseau 1 apps

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunder…

CVE-2024-0749
MEDIUM 4.3 Réseau 1 apps

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firef…

CVE-2024-0747
MEDIUM 6.5 Réseau 1 apps

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy…

CVE-2024-0746
MEDIUM 6.5 Réseau 1 apps

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde…

CVE-2024-0742
MEDIUM 4.3 Réseau 1 apps

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent …

CVE-2024-0741
MEDIUM 6.5 Réseau 1 apps

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox…

CVE-2024-23224
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

CVE-2024-23223
MEDIUM 6.2 Local

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An …

CVE-2024-23219
MEDIUM 6.2 Local

The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.

CVE-2024-23218
MEDIUM 5.9 Réseau

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPad…

CVE-2024-23215
MEDIUM 5.5 Local

An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. …

CVE-2024-23207
MEDIUM 5.5 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma…

CVE-2024-23206
MEDIUM 6.5 Réseau

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, ma…

CVE-2023-42937
MEDIUM 5.5 Local

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ve…

CVE-2023-42935
MEDIUM 5.5 Local

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the pre…

CVE-2023-42888
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS…

CVE-2023-42887
MEDIUM 6.3 Local

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able to read …

CVE-2023-40528
MEDIUM 5.5 Local

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6…

CVE-2022-42816
MEDIUM 5.5 Local

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file s…

CVE-2023-6860
MEDIUM 6.5 Réseau 1 apps

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe…

CVE-2023-6857
MEDIUM 5.3 Réseau 1 apps

When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni…

CVE-2023-50762
MEDIUM 4.3 Réseau 1 apps

When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w…

CVE-2023-50761
MEDIUM 4.3 Réseau 1 apps

The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t…

CVE-2023-51384
MEDIUM 5.5 Local

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of …

CVE-2023-49646
MEDIUM 6.4 Réseau 4 apps

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-43583
MEDIUM 4.9 Réseau 2 apps

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user …

CVE-2023-6507
MEDIUM 6.1 Réseau adjacent 1 apps

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. …

CVE-2023-45866
MEDIUM 6.3

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-42916
MEDIUM 6.5 KEV Réseau

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr…

CVE-2023-6209
MEDIUM 6.5 Réseau 1 apps

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. T…

CVE-2023-6206
MEDIUM 5.4 Réseau 1 apps

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact t…

CVE-2023-6205
MEDIUM 6.5 Réseau 1 apps

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability…

CVE-2023-6204
MEDIUM 6.5 Réseau 1 apps

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on t…

CVE-2023-43582
MEDIUM 5.5 Réseau 4 apps

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-39205
MEDIUM 4.3 Réseau 4 apps

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39204
MEDIUM 4.3 Réseau 4 apps

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39203
MEDIUM 4.3 Réseau 1 apps

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disc…